Engrym — Data Processing Addendum and Sub-processor Schedule
Provider / Processor: RTK AI Labs Ltd, a company registered in England and Wales under company number 17179962, provider of Engrym. Registered office: 66 Paul Street, London EC2A 4NA, England.
Customer / Controller: the entity or person agreeing to Engrym's Terms of Service.
Last updated: 3 July 2026
This Data Processing Addendum ("DPA") forms part of, and is subject to, the Terms of Service between the Customer and RTK AI Labs Ltd. RTK AI Labs Ltd is established in England and Wales (United Kingdom); the UK GDPR is the primary processor-side regime, with the EU GDPR applying to data subjects in the European Union, and appropriate transfer mechanisms applying where personal data leaves the UK or the EEA (see Section 8).
1. Subject matter and roles
RTK AI Labs Ltd processes personal data on the Customer's behalf to provide the Service described in the Terms of Service. For that personal data, the Customer is the controller and RTK AI Labs Ltd is the processor. For RTK AI Labs Ltd's own account, billing, and operational data, RTK AI Labs Ltd acts as controller (see the Privacy Policy).
2. Nature and purpose of processing
Storage, synchronization, AI-extraction of Atoms from Documents (dispatched on the Customer's own provider key, or performed by the Customer's own connected agent which pulls Document text and submits results back), semantic and keyword search, duplicate detection, contradiction-finding, export and portability, billing, and support — as configured by the Customer.
3. Categories of data subjects
The Customer's authorized users, and any individuals referenced within the Customer's Documents and Atoms. The Customer is responsible for ensuring it has a lawful basis for any personal data it includes in its content.
4. Categories of personal data
- Account identifiers (email, authentication identifiers).
- Customer content (Documents, Atoms, verdicts, intents, sessions, imported media), which may contain personal data the Customer chooses to include.
- Billing metadata (handled via the payment processor).
- Not processed: source code (see Section 11, the transient-sensor boundary); full card numbers (held by the payment processor); the credentials of any AI subscription the Customer's own agent runs on (never received).
5. Special-category data
The Service is not intended for special-category personal data. The Customer should not upload special-category data through the Service.
6. Duration
Personal data is processed for the term of the Customer's subscription plus the deletion and export window set out in the Privacy Policy, after which it is deleted or returned as described below.
7. Processor obligations
- Process on documented instructions only. RTK AI Labs Ltd processes Customer personal data only to provide the Service and on the Customer's documented instructions (these terms and the Customer's use of the Service).
- Confidentiality. Personnel authorized to process Customer data are bound by confidentiality.
- Security. RTK AI Labs Ltd maintains appropriate technical and organizational measures (see Section 9).
- Sub-processors. RTK AI Labs Ltd uses the sub-processors in the Schedule (Section 10) and gives notice of changes (Section 8).
- Assistance. RTK AI Labs Ltd assists the Customer, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations.
- Breach notification. RTK AI Labs Ltd notifies the Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data.
- Deletion or return on termination. On termination, RTK AI Labs Ltd deletes or returns Customer personal data per the Customer's choice, subject to any legally required retention. The Git export feature is the Customer's self-service return mechanism.
- Audit and information. RTK AI Labs Ltd makes available the information reasonably necessary to demonstrate compliance with this DPA.
8. International transfers and change notice
RTK AI Labs Ltd is established in the United Kingdom. Its core platform processors run in the European Union (database, authentication, and storage in AWS eu-west-1, Ireland; application compute pinned to Dublin) and the United Kingdom (the remote MCP connector and the background workers, in London). Where personal data is transferred outside the UK or the EEA — including, on the platform-funded path, the transfer of Atom text to Google, and any transfer arising because a hosting provider is a US company — RTK AI Labs Ltd relies on appropriate transfer mechanisms recognized under the UK GDPR and the EU GDPR.
Sub-processor change notice. RTK AI Labs Ltd maintains a current sub-processor list and gives notice of additions or changes before the new sub-processor begins processing Customer personal data.
9. Technical and organizational measures
- Encryption in transit: all Service traffic is encrypted over HTTPS.
- Encryption at rest: Customer provider keys are encrypted at rest using strong, industry-standard encryption; they are never stored in plaintext, are decrypted only momentarily in memory to dispatch a request, and are never logged or returned to any caller.
- Tenant isolation: strict logical isolation separates each Customer's data so that one Customer cannot access another's.
- Secret custody: application and provider secrets are held in managed secret storage and are never stored alongside Customer data.
- Log minimization: server-side request logs carry request metadata only; authorization headers, cookies, API keys, and idempotency keys are always redacted before a log line is written, and request bodies are not logged by default. The local Sync Daemon ships without third-party telemetry, and no third-party error-monitoring or analytics service is integrated.
- Backups and recovery: Customer data is backed up to support recovery in the event of failure or loss.
- Code-data exclusion: by design, no source code is processed or stored (see Section 11).
RTK AI Labs Ltd applies appropriate technical and organizational security measures to protect Customer personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
10. Sub-processor Schedule
RTK AI Labs Ltd engages the sub-processors below to process Customer personal data in connection with the Service.
10a. Core platform sub-processors
| # | Processor | Personal data processed | Purpose | Region |
|---|---|---|---|---|
| 1 | Supabase | Account identity, Documents, Atoms, verdicts and path:line pointers, intents, sessions, billing metadata, encrypted provider-key ciphertext, imported media. No source code. | Database, authentication, real-time sync, and storage. | European Union (AWS eu-west-1, Ireland) |
| 2 | Vercel | Requests and responses, session cookies, content in transit, server-side request logs (metadata only; bodies not logged by default). | Hosting (dashboard, landing site, API). | Compute pinned to the European Union (Dublin); static assets on Vercel's global edge network. Vercel is a US company. |
| 3 | Fly.io | MCP connector traffic (the Customer's agent requests and responses, including Document and Atom text in transit), extraction work-queue data, Git-export payload (Documents, knowledge base, decision log, activity stream). No source code. | Hosting for the remote MCP connector and the background workers (extraction, Git export, conflict detection). | United Kingdom (London). Fly.io is a US company. |
| 4 | Stripe | Email, subscription status, payment method (held by Stripe), customer and subscription identifiers, invoice metadata. No card numbers stored by Engrym. | Subscription billing. | Determined by the processor |
| 5 | Resend | Email, consent state, and delivery events. Newsletter only. | Newsletter delivery. | Determined by the processor |
10b. AI provider sub-processors — your-key (BYOK) vs platform-funded (kept separate)
| # | Path | Processor(s) | Personal data | Whose key | Region |
|---|---|---|---|---|---|
| 6 | Your-key (BYOK) inference — extraction (Documents to Atoms, in BYOK and mix modes) and contradiction-finding | The AI provider the Customer selects (Anthropic, OpenAI, or Google) | Document text; Atom text. No source code. | Customer's key (encrypted at rest; single-use decrypt). | Determined by the provider; governed by the Customer's own agreement with that provider. |
| 7 | Platform-funded inference — semantic-search embeddings and duplicate detection | Google (Gemini API) | Atom text only. No source code; no Document content beyond the Atom text. | Engrym's Platform Key. | Determined by the provider. |
Agent-mode extraction is not a sub-processing path. Where the Customer sets a Project to agent mode, extraction runs inside the Customer's own AI agent, on the Customer's own AI subscription, in the Customer's own environment: Engrym serves Document text to the Customer's agent and records the submitted results as provisional Atoms. RTK AI Labs Ltd dispatches nothing to any AI provider for that work and never receives the Customer's subscription credentials; the Customer's agent and its AI provider act for the Customer, not as RTK AI Labs Ltd's sub-processors.
11. The transient-sensor boundary (data RTK AI Labs Ltd does not process)
By design, RTK AI Labs Ltd does not read, store, embed, index, cache, or persist any representation of source code — no file contents, abstract syntax tree, call graph, import graph, file tree, snippet, or code text in a verdict beyond the path:line pointer. Reconciliation runs in the Customer's own agent session; RTK AI Labs Ltd receives only the verdict. Source code is therefore outside the scope of this DPA, because it is never processed by RTK AI Labs Ltd.
12. Document history
- 3 July 2026 — Schedule corrected to match verified infrastructure: Fly.io hosts the remote MCP connector and the background workers (extraction, Git export, conflict detection) — not only a Git-export worker — and runs in the United Kingdom (London); the previously listed United States region for a standalone export worker was never deployed and is removed. Error-monitoring and uptime-monitoring vendors were removed from the schedule: no such service is integrated in the product today, and the uptime checks that do exist are synthetic probes of a public endpoint that carry no Customer personal data. Supabase and Vercel regions stated precisely (verified). Section 2 and Schedule 10b now describe agent-mode extraction, in which the Customer's own agent performs extraction on the Customer's own subscription. Log-minimization measure restated to match the shipped logging behavior.
- 19 June 2026 — First published version.